ExpressRoute Microsoft Peering and other tenants

SmithJamesUK-9730 0 Reputation points
2024-01-23T08:51:18.5266667+00:00

If an organisation has ExpressRoute with Microsoft peering enabled, is ER used for all traffic for enabled service tags or only those services hosted in the same tenant? Example scenario: connecting to a storage account hosted in a customer's tenant rather than my organisation?

Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
340 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. ChaitanyaNaykodi-MSFT 24,231 Reputation points Microsoft Employee
    2024-01-24T02:47:18.53+00:00

    @SmithJamesUK-9730

    Thank you for reaching out.

    Based on your questions above

    If an organisation has ExpressRoute with Microsoft peering enabled, is ER used for all traffic for enabled service tags or only those services hosted in the same tenant?

    Yes, it is enabled for the service tags. As documented here

    If your ExpressRoute circuit is enabled for Azure Microsoft peering, you can access the public IP address ranges used in Azure over the circuit. Azure Microsoft peering provides access to services currently hosted on Azure (with geo-restrictions depending on your circuit's SKU). To validate availability for a specific service, you can check the documentation for that service to see if there's a reserved range published for that service. Then, look up the IP ranges of the target service and compare with the ranges listed in the Azure IP Ranges and Service Tags – Public Cloud XML file.

    Example scenario: connecting to a storage account hosted in a customer's tenant rather than my organisation?

    Yes, you can access the storage account hosted in a customer's tenant over Microsoft Peering. For storage account with Network restriction, to allow access to your service resources, you must allow these public IP addresses in the firewall setting for resource IPs. For Microsoft peering, either the service provider or the customer provides the NAT IP addresses. More details can be found here.

    Below are some helpful FAQ's regarding this set-up.

    Hope this helps! Please let me know if you have any additional questions. Thank you!


    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments